IBM Support

Security Bulletin: Multiple vulnerabilities in IBM Financial Transaction Manager for ACH Services, Check Services and Corporate Payment Services

Security Bulletin


Summary

Multiple vulnerabilities in IBM Financial Transaction Manager for ACH Services, Check Services and Corporate Payment Services. Note the description says ACH Services but the vulnerabilities also apply to Check and CPS.

Vulnerability Details

CVEID: CVE-2016-0253
DESCRIPTION:
IBM Financial Transaction Manager for ACH Services for Multi-Platform is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVSS Base Score: 5.4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110562 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
CVEID: CVE-2016-0268
DESCRIPTION:
IBM Financial Transaction Manager for ACH Services for Multi-Platform could allow a remote authenticated attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML. A remote attacker could exploit this vulnerability to read sensitive information on the system.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/110915 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)

CVEID: CVE-2016-0272
DESCRIPTION:
IBM Financial Transaction Manager for ACH Services for Multi-Platform is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.
CVSS Base Score: 8
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/111052 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)

CVEID: CVE-2016-0274
DESCRIPTION:
IBM Financial Transaction Manager for ACH Services for Multi-Platform could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions.
CVSS Base Score: 4.3
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/111076 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)

CVEID: CVE-2016-0275
DESCRIPTION:
IBM Financial Transaction Manager for ACH Services for Multi-Platform could allow a local attacker to obtain sensitive information due to cacheable HTTPS responses that are stored locally.
CVSS Base Score: 4
CVSS Temporal Score: See for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

CVEID: CVE-2016-0276
DESCRIPTION:
IBM Financial Transaction Manager for ACH Services for Multi-Platform could allow a remote attacker to execute arbitrary code on the system,. An attacker could exploit this vulnerability using a specially crafted serialized Java Message Service (JMS) ObjectMessage object to execute arbitrary code on the system.
CVSS Base Score: 5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/111084 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

- FTM for ACH v3.0.0.0, v3.0.0.1, v3.0.0.2, v3.0.0.3, v3.0.0.4, v3.0.0.5, v3.0.0.6, v3.0.0.7, v3.0.0.8, v3.0.0.9, v3.0.0.10, 3.0.0.11, 3.0.0.12

- FTM for Check v3.0.0.0, v3.0.0.1, v3.0.0.2, v3.0.0.3, v3.0.0.4, v3.0.0.5, v3.0.0.6, v3.0.0.7, v3.0.0.8, v3.0.0.9, v3.0.0.10, 3.0.0.11, 3.0.0.12

- FTM for CPS v3.0.0.0, v3.0.0.1, v3.0.0.2, v3.0.0.3, v3.0.0.4, v3.0.0.5, v3.0.0.6, v3.0.0.7, v3.0.0.8, v3.0.0.9, v3.0.0.10, 3.0.0.11, 3.0.0.12

Remediation/Fixes

Product VRMF APAR Remediation/First Fix
FTM for ACH Services 3.0.0.0 through 3.0.0.12 PI57470 Apply 3.0.0-FTM-ACH-MP-fp0013 or later.
FTM for Check Services 3.0.0.0 through 3.0.0.12 PI57471 Apply 3.0.0-FTM-Check-MP-fp0013 or later.
FTM for CPS Services 3.0.0.0 through 3.0.0.12 PI57472 Apply 3.0.0-FTM-CPS-MP-fp0013 or later.

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Related information

Change History

31 March 2016: Original version published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.

Document information

More support for: Financial Transaction Manager
IBM Financial Transaction Manager for ACH Services

Software version: 3.0.0.0, 3.0.0.1, 3.0.0.2, 3.0.0.3, 3.0.0.4, 3.0.0.5, 3.0.0.6, 3.0.0.7, 3.0.0.8, 3.0.0.9, 3.0.0.10, 3.0.0.11, 3.0.0.12

Operating system(s): AIX, Linux, Windows

Reference #: 1977245

Modified date: 31 March 2016


Translate this page: